Vulnerabilities
Vulnerable Software
Zettlr:  Security Vulnerabilities
Zettlr version 2.3.0 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Zettlr. This is possible because the application does not have a CSP policy (or at least not strict enough) and/or does not properly validate the contents of markdown files before rendering them.
CVSS Score
5.5
EPSS Score
0.0
Published
2022-11-03
No filtering of cross-site scripting (XSS) payloads in the markdown-editor in Zettlr 1.8.7 allows attackers to perform remote code execution via a crafted file.
CVSS Score
6.1
EPSS Score
0.006
Published
2021-06-18
Cross-site scripting vulnerability in Zettlr from 0.20.0 to 1.8.8 allows an attacker to execute an arbitrary script by loading a file or code snippet containing an invalid iframe into Zettlr.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-05-27


Contact Us

Shodan ® - All rights reserved